80
Mode
Working process
Principle
Application scenario
Multicast
A multicast server periodically
sends clock synchronization
messages to the user-configured
multicast address. Clients listen
to the multicast messages from
servers and synchronize to the
server according to the received
messages.
A multicast client can
synchronize to a
multicast server, but a
multicast server cannot
synchronize to a
multicast client.
A multicast server can
provide time
synchronization for clients
in the same subnet or in
different subnets.
The multicast mode has a
lower time accuracy than
the client/server and
symmetric active/passive
modes.
In this document, an "NTP server" or a "server" refers to a device that operates as an NTP server in
client/server mode. Time servers refer to all the devices that can provide time synchronization,
including NTP servers, NTP symmetric peers, broadcast servers, and multicast servers.
NTP security
To improve time synchronization security, NTP provides the access control and authentication
functions.
NTP access control
You can control NTP access by using an ACL. The access rights are in the following order, from least
restrictive to most restrictive:
•
Peer
—Allows time requests and NTP control queries (such as alarms, authentication status,
and time server information) and allows the local device to synchronize itself to a peer device.
•
Server
—Allows time requests and NTP control queries, but does not allow the local device to
synchronize itself to a peer device.
•
Synchronization
—Allows only time requests from a system whose address passes the access
list criteria.
•
Query
—Allows only NTP control queries from a peer device to the local device.
The device processes an NTP request, as follows:
•
If no NTP access control is configured,
peer
is granted to the local device and peer devices.
•
If the IP address of the peer device matches a
permit
statement in an ACL for more than one
access right, the least restrictive access right is granted to the peer device. If a
deny
statement
or no ACL is matched, no access right is granted.
•
If no ACL is created for an access right, the associated access right is not granted.
•
If no ACL is created for any access right,
peer
is granted.
This feature provides minimal security for a system running NTP. A more secure method is NTP
authentication.
NTP authentication
Use this feature to authenticate the NTP messages for security purposes. If an NTP message
passes authentication, the device can receive it and get time synchronization information. If not, the
device discards the message. This function makes sure the device does not synchronize to an
unauthorized time server.
Summary of Contents for FlexNetwork 10500 SERIES
Page 224: ...213 ...
Page 311: ...300 Now the system can record log information to the specified file ...